• Open Menu Close Menu
  • Apple
  • Shopping Bag
  • Apple
  • Mac
  • iPad
  • iPhone
  • Watch
  • TV
  • Music
  • Support
  • Search apple.com
  • Shopping Bag

Lists

Open Menu Close Menu
  • Terms and Conditions
  • Lists hosted on this site
  • Email the Postmaster
  • Tips for posting to public mailing lists
Re: [iPhone] Data protection clarification needed.
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [iPhone] Data protection clarification needed.


  • Subject: Re: [iPhone] Data protection clarification needed.
  • From: Greg Guerin <email@hidden>
  • Date: Mon, 2 Aug 2010 11:29:16 -0700

Sandro Noël wrote:

There is no need for that data to be backed up anywhere, as it is retrievable from the web service.
the cached data is used for offline operations and later synced back to the web service.


We want to control when the data becomes available in an unencrypted format.
and that would be when our application is the active application, otherwise in the background or
terminated, the data is encrypted and inaccessible.


Then you need encryption and key management. When your application becomes inactive, the protected data must become inaccessible. That means you must securely delete the decryption key. When your application becomes active, you must securely obtain a decryption key, which allows access to the protected data. There are different ways of doing those things. If you don't have good key management, it won't matter how well the data is encrypted, because an easily accessible key is the weakest point.

You might get better or more specific advice on the CDSA list:
http://lists.apple.com/mailman/listinfo/apple-cdsa

CDSA = Common Data Security Architecture

  -- GG

_______________________________________________

Cocoa-dev mailing list (email@hidden)

Please do not post admin requests or moderator comments to the list.
Contact the moderators at cocoa-dev-admins(at)lists.apple.com

Help/Unsubscribe/Update your Subscription:
This email sent to email@hidden


  • Prev by Date: Re: Unarchiving issues
  • Next by Date: Detecting a remote volume
  • Previous by thread: Re: [iPhone] Data protection clarification needed.
  • Next by thread: NSURLConnection - data comes in after completion
  • Index(es):
    • Date
    • Thread